SUSE

First CVE: May 13, 2019Active for: 7 years
244
CVEs Published
More CVEs Published than 81% of tracked CNAs
30.5
Avg CVEs / Year
More Avg CVEs / Year than 77% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by SUSE as a CNA, 50.0% affect products that SUSE develops as a vendor.

50.0%
50.0%
Self-reported: 122Third-party: 122

Of all the CVEs published that affect products developed by SUSE, 10.0% are self-published by SUSE as a CNA.

90.0%
Self-published: 122Published by other CNAs: 1,103

Trends Over Time

The number and severity of CVEs published by SUSE over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 13, 2019
7 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by SUSE as a CNA, regardless of affected vendor or product.

244 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any command as root on any client. 
Jul 30, 20259.853NOYES
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be us
Jul 2, 20269.943NONO
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as
Jul 2, 202610.043NONO
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to us
Sep 7, 20229.943NOYES
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overw
Jul 2, 20268.840NONO
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used
Jul 8, 20268.839NONO
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code withi
Jul 8, 20268.839NONO
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.
Jul 8, 20268.839NONO
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.
Jun 29, 20268.839NONO
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets fro
May 13, 20269.939NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA244 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local113 (46.3%)
Network124 (50.8%)
Unknown0 (0.0%)
Physical1 (0.4%)
Adjacent Network5 (2.0%)
Attack Complexity
Low221 (90.6%)
High23 (9.4%)
Unknown0 (0.0%)
User Interaction
None196 (80.3%)
Unknown0 (0.0%)
Required42 (17.2%)
Privileges Required
Low147 (60.2%)
High21 (8.6%)
None76 (31.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (244 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.8% of CVEs· 86th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.4% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by SUSE as a CNA.

Media Mentions

Media articles that mention a CVE ID published by SUSE as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs